US2015242840A1PendingUtilityA1

Systems and methods for dynamic biometric configuration compliance control

Assignee: JPMORGAN CHASE BANK NAPriority: Feb 25, 2014Filed: Feb 25, 2014Published: Aug 27, 2015
Est. expiryFeb 25, 2034(~7.6 yrs left)· nominal 20-yr term from priority
Inventors:Eren Kursun
G06Q 20/40145G06Q 20/4016G06Q 20/3224G06F 21/32G06F 21/552G06F 2221/2113G06F 2221/2111
60
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

Systems and methods for dynamically-configured compliance control are disclosed. According to one embodiment, a method may include (1) receiving, from an electronic device, a transaction request for a user that requires authentication; (2) at least one computer processor determining a target security level for the transaction; (3) the at least one computer processor determining a location of the electronic device; (4) the at least one computer processor determining at least one restriction on conducting the transaction based on the location of the electronic device; (5) the at least one computer processor determining at least one authentication configuration that meets the target security level and the at least one restriction on conducting the transaction; and (6) the at least one computer processor receiving user data in accordance with the authentication configuration.

Claims

exact text as granted — not AI-modified
1 . A method for dynamically-configured compliance control, comprising:
 receiving, from an electronic device, a transaction request for a user that requires authentication;   at least one computer processor determining a target security level for the transaction;   the at least one computer processor determining a location of the electronic device;   the at least one computer processor determining at least one restriction on conducting the transaction based on the location of the electronic device;   the at least one computer processor determining at least one authentication configuration that meets the target security level and the at least one restriction on conducting the transaction, the authentication configuration comprising at least one of an authentication modality and an electronic device configuration; and   the at least one computer processor receiving user data in accordance with the authentication configuration.   
     
     
         2 . The method of  claim 1 , further comprising:
 the at least one computer processor determining at least one risk factor based on historical transaction data for at least one of the user and a type for the transaction.   
     
     
         3 . The method of  claim 1 , further comprising:
 the at least one computer processor performing statistical analysis on the transaction.   
     
     
         4 . The method of  claim 1 , further comprising:
 the at least one computer processor analyzing at least one of the transaction and the user for an anomaly.   
     
     
         5 . The method of  claim 1 , wherein the restriction is on a manner of user authentication. 
     
     
         6 . The method of  claim 1 , wherein the restriction is at least one legal requirement on a manner in which the transaction is conducted. 
     
     
         7 . The method of  claim 6 , wherein the at least one legal requirement is one of a law and a regulation. 
     
     
         8 . The method of  claim 6 , wherein the at least one legal requirement comprises at least a first level legal requirement and a second level legal requirement. 
     
     
         9 . The method of  claim 8 , further comprising:
 the at least one computer processor determining a hierarchy associated with first level legal requirement and the second level legal requirement; and   the at least one computer processor selecting the restriction based on the determination.   
     
     
         10 . The method of  claim 1 , further comprising:
 the at least one computer processor determining at least one policy restriction on conducting the transaction; and   wherein the at least one computer processor determines the at least one authentication configuration to meet the target security level, the at least one restriction on conducting the transaction, and the policy restriction.   
     
     
         11 . The method of  claim 1 , wherein the authentication modality is selected from a plurality of available authentication modalities. 
     
     
         12 . The method of  claim 1 , wherein the electronic device configuration is based on at least one electronic device specification. 
     
     
         13 . The method of  claim 12 , wherein the electronic device specification identifies a characteristic for an available input on the electronic device. 
     
     
         14 . The method of  claim 1 , further comprising:
 completing the transaction with the authentication configuration.   
     
     
         15 . The method of  claim 1 , wherein the authentication configuration comprises at least one biometric. 
     
     
         16 . The method of  claim 1 , wherein there are a plurality of hierarchies for a plurality of restrictions, and wherein the at least one computer determines at least one authentication configuration by one of merging the hierarchies and resolving conflicts in the hierarchies. 
     
     
         17 . A system for dynamic compliance control, comprising:
 a user electronic device comprising:
 at least one computer processor that receives a transaction request from a user; and 
 a compliance interface executed by the at least one computer processor; 
   a back-end comprising:
 at least one interface for receiving the transaction request from the compliance interface; 
 a restriction matrix that stores at least one transaction restriction; and 
 at least one back-end computer processor that performs the following:
 determine a target security level for the transaction; 
 determine at least one restriction on conducting the transaction based on the location of the electronic device; 
 determine at least one authentication configuration that meets the target security level and the at least one restriction on conducting the transaction, the authentication configuration comprising at least one of an authentication modality and an electronic device configuration; and 
 receive user data in accordance with the authentication configuration. 
 
   
     
     
         18 . The system of  claim 17 , wherein the at least one back-end computer processor further determines at least one risk factor based on historical transaction data for at least one of the user and a type for the transaction. 
     
     
         19 . The system of  claim 17 , wherein the back-end further comprises a statistical analysis engine that performs statistical analysis on the transaction. 
     
     
         20 . The system of  claim 17 , wherein the back-end further comprises an anomaly engine that analyzes at least one of the transaction and the user for an anomaly. 
     
     
         21 . The system of  claim 17 , wherein the restriction is on a manner of user authentication. 
     
     
         22 . The system of  claim 17 , wherein the restriction is at least one legal requirement on a manner in which the transaction is conducted. 
     
     
         23 . The system of  claim 22 , wherein the at least one legal requirement comprises at least first level legal requirement and a second level legal requirement 
     
     
         24 . The system of  claim 22 , wherein the back-end processor further:
 determines a hierarchy associated with first level legal requirement and the second level legal requirement; and   selects the restriction based on the determination.   
     
     
         25 . The system of  claim 17 , wherein the back-end processor further:
 determines at least one policy restriction on conducting the transaction; and   determines the at least one authentication configuration to meet the target security level, the at least one restriction on conducting the transaction, and the policy restriction.   
     
     
         26 . The system of  claim 17 , wherein the authentication modality is selected from a plurality of available authentication modalities. 
     
     
         27 . The system of  claim 17 , wherein the electronic device configuration is based on at least one electronic device specification. 
     
     
         28 . The system of  claim 27 , wherein the electronic device specification identifies a characteristic for an available input on the electronic device. 
     
     
         29 . The system of  claim 17 , wherein the authentication configuration comprises at least one biometric. 
     
     
         30 . The system of  claim 17 , wherein the user electronic device further comprises a cache version of the restriction matrix.

Join the waitlist — get patent alerts

Track US2015242840A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.